Share your thoughts, 1 month free Claude Pro on usSee more
WorkDL logo mark

GuardReasoner: Towards Reasoning-based LLM Safeguards

About

As LLMs increasingly impact safety-critical applications, ensuring their safety using guardrails remains a key challenge. This paper proposes GuardReasoner, a new safeguard for LLMs, by guiding the guard model to learn to reason. Concretely, we first create the GuardReasonerTrain dataset, which consists of 127K samples with 460K detailed reasoning steps. Then, we introduce reasoning SFT to unlock the reasoning capability of guard models. In addition, we present hard sample DPO to further strengthen their reasoning ability. In this manner, GuardReasoner achieves better performance, explainability, and generalizability. Extensive experiments and analyses on 13 benchmarks of 3 guardrail tasks demonstrate its superiority. Remarkably, GuardReasoner 8B surpasses GPT-4o+CoT by 5.74% and LLaMA Guard 3 8B by 20.84% F1 score on average. We release the training data, code, and models with different scales (1B, 3B, 8B) of GuardReasoner : https://github.com/yueliu1999/GuardReasoner/.

Yue Liu, Hongcheng Gao, Shengfang Zhai, Yufei He, Jun Xia, Zhengyu Hu, Yulin Chen, Xihong Yang, Jiaheng Zhang, Stan Z. Li, Hui Xiong, Bryan Hooi• 2025

Related benchmarks

TaskDatasetResultRank
Response Harmfulness DetectionHarmBench
F1 Score96.31
100
Response Harmfulness DetectionXSTEST-RESP
Response Harmfulness F194.34
76
Response Harmfulness DetectionBeavertails
F1 Score87.6
59
Safety ClassificationSafeRLHF
F1 Score0.7004
48
Harmfulness DetectionWildGuard
Macro F1 Score89.17
47
Toxicity DetectionToxicChat
F1 Score0.7879
45
Harmfulness DetectionOpenAI Moderation
Macro F1 Score72
45
Prompt Harmfulness DetectionAegisSafety (test)
F1 Score91.39
41
Response Harmfulness DetectionSafeRLHF
F1 Score70.04
41
Response ClassificationBeaverTails V Text-Image Response
F1 Score84.02
39
Showing 10 of 63 rows

Other info

Follow for update